Tech support: What anti-virus program do you use?Heh. If that's your thing, you'll find more here. Some are hilarious.
Customer: Firefox.
Tech support: That's not an anti-virus program.
Customer: Oh, sorry...Internet Explorer.
Wednesday, January 21, 2009
Security Humor
It's kind of all-security-all-the-time here today, so to lighten the mood, a tech support call to the security helpdesk:
Everybody Polka Patch!
In the Brave New World that is Web 2.0, everyone's going to use their browser for everything. Word Processor? Google Documents, via your browser. Email? Gmail, via your browser. Remote login? Thin Client, via (you guessed it) your browser.
What made the buzz get cranked all the way up to 11 is that you don't need to care about what computer people use to connect. Use whatever you want. Windows? Sure. Linux? OK, geek boy. Mac? Get your Think Different cult on. Everyone plays!
So what happens when there's a security bug in the browser? Ah, but there are so many browsers. Firefox, Internet Explorer, Opera, Chrome. They can't all be bad, right?
Wrong. OK, technically, they're not vulnerable. But they run Quicktime, which is vulnerable, and which is all over Al Gore's Intarwebz. All browsers run Quicktime. And Quicktime has a nasty bug that will get you pwned, no matter who you are.
So clicky here to patch. Yes, you.
What made the buzz get cranked all the way up to 11 is that you don't need to care about what computer people use to connect. Use whatever you want. Windows? Sure. Linux? OK, geek boy. Mac? Get your Think Different cult on. Everyone plays!
So what happens when there's a security bug in the browser? Ah, but there are so many browsers. Firefox, Internet Explorer, Opera, Chrome. They can't all be bad, right?
Wrong. OK, technically, they're not vulnerable. But they run Quicktime, which is vulnerable, and which is all over Al Gore's Intarwebz. All browsers run Quicktime. And Quicktime has a nasty bug that will get you pwned, no matter who you are.
So clicky here to patch. Yes, you.
A good day for bad news
Yesterday was Coronation Inauguration Day, and the press was (ahem) busy. That made it the best day in recent memory to bury bad news. After all, the press simply wasn't interested in much else.
So what kind of bad news might be good to bury? How about the biggest compromise of credit cards in history? Hackers stealing a hundred million cards - what, didn't you hear?
I have to hand it to Heartland's PR department. They chose the announcement timing very, very well.
UPDATE 21 January 2009 20:12: Rich Mogul has more about the way the hack was done.
UPDATE 21 January 2009 20:37: Uh oh - my secret's out. I get my security news at Liberty's place ...
Heh.
So what kind of bad news might be good to bury? How about the biggest compromise of credit cards in history? Hackers stealing a hundred million cards - what, didn't you hear?
Hearland Payment Systems, a credit card payment processor, apparently chose the completely innocuous day of January 20th, 2009 to inform the world that a data breach occured, and that it did not affect any “merchant data or cardholder Social Security numbers, unencrypted PINs, addresses or telephone numbers”. What possibly was affected, however, was every credit card number that traversed their payment processing system.So, Mr. Good-Day-To-Hide-Bad-News PR Man, just who might that be? Well, did you ever use a credit card?
Anyone who used a Visa or Mastercard at one of a quarter of a million businesses may have been affected. For the small number of you who fall into this category, I recommend going through your old credit card statements just in case you were one of the victims. In all honesty, the probability of any one person being victimized by this is pretty slim, but vigilance is never a bad thing.Oops. Glad that everyone's getting the word.
I have to hand it to Heartland's PR department. They chose the announcement timing very, very well.
UPDATE 21 January 2009 20:12: Rich Mogul has more about the way the hack was done.
UPDATE 21 January 2009 20:37: Uh oh - my secret's out. I get my security news at Liberty's place ...
Heh.
New Shooter
Don from the officehas been following my shooting for some time. He's actually been shooting before, with his dad when he was 8. Since he's my age (i.e. an old fart), this was a long, long time ago. He didn't enjoy the experience, probably because his dad had an odd choice of guns for an 8 year old: a derringer in .38 special (probably something like this), and a .30-06 hunting rifle.
Actually, I think his shoulder is still sore from that experience.
I was a little surprised when he took me up on the shooting offer, because his wife is extremely anti-gun. She grew up in Brazil under the Generals - they were corrupt, brutal, and armed, which is a bad combination.
The first thing about taking a new shooter is safety, and Don was a quick study with the Four Rules. The question then is what to shoot? A .22 pistol is often recommended for beginners, and for good reason - almost no recoil, moderately quiet, easy to control. But Don's a big guy, and knew what to expect (he's from the south, and most of his family is still there with their guns); while we didn't talk about it in so many words, it seemed like getting back on the horse was what was called for.
But not with a derringer. The Ruger SP101 is heavy, so there's a lot of mass to soak up the recoil. The .38 cartridge is certainly a step up from a .22, but is not overpowering. And it's a revolver - what's nice about it for a new shooter is that the design is dead simple: everyone understands how it works. There are no controls other than the bang-switch. Simple, simple, simple.
Plus you can shoot it single action. Single action is always more accurate than double action (in a revolver), and more accurate means the new shooter has more fun. After the first five rounds (making friends with Mr. Revolver), Don was sending all the bullets into the X Ring, often through the same holes (that's his shooting on the target in the picture).
Not bad for not having shot in (mumble) years!
I wanted to do a "compare and contrast" exercise with an autoloader, and "simple" means Glock. Now you've added two controls: a magazine release and a slide release, but that's it.
This was a step up from the SP101, recoil-wise, and it opened Don's groupings up a bit. Still, everything was in the 9 ring or better (once again, the results of Don's shooting is shown in the picture).
When we were done, we both had the expected big grins. He'll come back, which will be very nice indeed - it's always nice to add a shooting buddy. He's also thinking about taking his Son-in-law, which is also nice.
Likely it's an uphill battle to get his wife to the range. Her childhood had some traumatic episodes that involved bad guys with guns; worse, they were from the government and were definitely not there to help. Here in the USA we're lucky that way. I suggested that the Second Amendment was not there by accident, and this seemed to strike a nerve.
So not a bad day - shooty goodness with a friend at the range, and new shooter, and a civics lesson all rolled into one.
UPDATE 24 January 2009 09:34: Welcome visitors from StumbleUpon! I have some more New Shooter Reports, and some Range Reports too. If you like what you see, come back again sometime! My best posts are here.
Actually, I think his shoulder is still sore from that experience.
I was a little surprised when he took me up on the shooting offer, because his wife is extremely anti-gun. She grew up in Brazil under the Generals - they were corrupt, brutal, and armed, which is a bad combination.
The first thing about taking a new shooter is safety, and Don was a quick study with the Four Rules. The question then is what to shoot? A .22 pistol is often recommended for beginners, and for good reason - almost no recoil, moderately quiet, easy to control. But Don's a big guy, and knew what to expect (he's from the south, and most of his family is still there with their guns); while we didn't talk about it in so many words, it seemed like getting back on the horse was what was called for.But not with a derringer. The Ruger SP101 is heavy, so there's a lot of mass to soak up the recoil. The .38 cartridge is certainly a step up from a .22, but is not overpowering. And it's a revolver - what's nice about it for a new shooter is that the design is dead simple: everyone understands how it works. There are no controls other than the bang-switch. Simple, simple, simple.
Plus you can shoot it single action. Single action is always more accurate than double action (in a revolver), and more accurate means the new shooter has more fun. After the first five rounds (making friends with Mr. Revolver), Don was sending all the bullets into the X Ring, often through the same holes (that's his shooting on the target in the picture).
Not bad for not having shot in (mumble) years!
I wanted to do a "compare and contrast" exercise with an autoloader, and "simple" means Glock. Now you've added two controls: a magazine release and a slide release, but that's it.This was a step up from the SP101, recoil-wise, and it opened Don's groupings up a bit. Still, everything was in the 9 ring or better (once again, the results of Don's shooting is shown in the picture).
When we were done, we both had the expected big grins. He'll come back, which will be very nice indeed - it's always nice to add a shooting buddy. He's also thinking about taking his Son-in-law, which is also nice.
Likely it's an uphill battle to get his wife to the range. Her childhood had some traumatic episodes that involved bad guys with guns; worse, they were from the government and were definitely not there to help. Here in the USA we're lucky that way. I suggested that the Second Amendment was not there by accident, and this seemed to strike a nerve.
So not a bad day - shooty goodness with a friend at the range, and new shooter, and a civics lesson all rolled into one.
UPDATE 24 January 2009 09:34: Welcome visitors from StumbleUpon! I have some more New Shooter Reports, and some Range Reports too. If you like what you see, come back again sometime! My best posts are here.
Tuesday, January 20, 2009
The Four Rules of Wii Safety
1. Always use the Wiimote wriststrap.Otherwise, you might have an unintentional, err, "discharge".
2. Always use the Wiimote wriststrap.
3. Always use the Wiimote wriststrap.
4. Always use the Wiimote wriststrap.
Mac Fanboys, get your NSA security guide
Really. It was made in the NSA; you know they make great stuff ...
Don't be too CNN!
Of course, it sounds better in the original Chinese:
* If you hadn't guessed, this is Chinese Internet slang.
There's more, much more at The Dark Visitor, your one-stop shop for hip Chinese Internet slang. Me? I just buy soy sauce*.1. Don’t be too CNN | zuò rén bùnéng tài CNN | 做人不能太CNN
Meaning: A synonym for a malicious frame up and blurring of the line between right and wrong.
Background: During the smashing, looting, and arson this March in Lhasa (known now as ‘3-14’ after the date), a news report by CNN used a photo cropped so it appeared Chinese military officers in a truck were attacking protestors. The undoctored picture, in fact, shows a group of protestors lobbing rocks at said vehicle.
* If you hadn't guessed, this is Chinese Internet slang.
De-Worm your Windows Computer

I posted last week about the new Uberworm that has everyone talking. Well, me and 9 million infected PCs that are spewing Spam as we speak. Don't be one of them.
Microsoft makes a free Malware Removal Tool that you should use, which should pretty painlessly de-worm you if you need it. While you're there, you should make sure that you have the patch for the bug that the worm is exploiting. You'll have to reboot after installing it, but hey, it's Windows!
Besides, it's orange flavored ...
iShot The Sheriff

New iPhone app to help yer Boomershoot score.
Tap in the variables such as weather conditions, ammunition type, distance to target, and wind speed before exhaling and gently squeezing back on your second amendment right.Hat tip to El Reg, from which I shamelessly stole the post title.
You may be Tactical, but you're not Tacticool
Without a minigun in your SUV, that is.

Dude, you're going to scratch the nice paintjob with all that brass ...
They have video, which I have to admit is pretty darn impressive. Plus pix of the new presidential limo, Cadillac One.
Via a Facebook post by Gene Spafford, a real security guru.
Dude, you're going to scratch the nice paintjob with all that brass ...
They have video, which I have to admit is pretty darn impressive. Plus pix of the new presidential limo, Cadillac One.
Via a Facebook post by Gene Spafford, a real security guru.
Monday, January 19, 2009
That's a bug, not a feature
What's wrong with this picture?
Both my regular readers are probably thinking what's wrong is that we're going to get another rant about online banking. Well, yes you are, but that's not the point. Buckle up, because I'm about to roll out Borepatch's Second Law of Security.
Let's think about a brick-and-mortar bank. It will be in a building with decent security. More importantly, the security will be well understood. There are people whose business it is to know how long it will take someone to knock a hole in drywall, or cinder block, or vault steel. Or bullet-proof glass, for that matter. When you design a bank branch office, you take these things into account.
You also take area characteristics into account. Is it a good neighborhood? High traffic? Well lighted? All of these effect the security of your customers when they're not in your building. The system of the branch office is more than just the building.
So what's the system of the online mobile bank? We need to understand this to understand the risks of the different system components to get a good understanding of the overall risk.
There's the web site itself (logo blurred out here to protect the guilty). My experience is that you'll find the best security in the Defense Department. Very close behind that is security at the major banks. I have made some snide comments in the past about online banking, but the problem isn't that they don't have cutting-edge technology, or skilled operations personnel, or processes and procedures that are backed by executive management. Someone's in charge of the system - you can ask the question who's the online security guy and get an answer. While there will always be the occasional security vulnerability in the web portal, the risk here is low.
There's the Internet, that sits between you and the web site. Security is lousy here, but the encryption used to scramble your data while it flies over Al Gore's Intarwebz is so good that the risk here is basically non-existent.
There's your phone, and your phone's browser. Technology is moving very, very fast here, which means that security is an after thought. You have many different vendors - one makes the phone, a different one makes the software, and a third one that sets everything up. For me, it's some company in China who makes the phone, and Apple who makes the software (OS X and Safari), and AT&T who sets things up.
So when it comes to your phone, you are the "online security guy". You need to configure the phone securely and make sure that things are working correctly. Not your bank - after all, it's your phone, not theirs.
So what's the risk of the overall banking system? Negligible risk in the banking web site and Internet transport, but indeterminate risk in your phone.
In an engineering sense, "indeterminate" is a Bad Thing, because you can't estimate costs and risks. It's more than just Ted has a bad feeling going on here, there are serious issues that you need to know before you know if the overall online mobile banking system has unacceptable risk:
So we're back to indeterminate. This is Bad Security juju, and this is where I will point to Borepatch's Second Law of Security:
Imagine now that instead of naughty pix of the little lady, Mr. Sherman had his banking account and password on his phone.
Indeterminate.
So if you know how the system works and think that the benefits outweight the costs, then go ahead. That, in fact, is the way that the system is supposed to work. As for me, I don't think I'm smart enough to figure out what my phone is doing.
So my recommendation to you is use an ATM, or if you absolutely must bank online, use your home computer. Just follow the 2 Simple Rules for Safer Browsing.
Your mileage may vary, void where prohibited, do not remove under penalty of law.
UPDATE 19 January 2009 21:14: Chris Byrne left a information-rich comment that is well worth your while.
Both my regular readers are probably thinking what's wrong is that we're going to get another rant about online banking. Well, yes you are, but that's not the point. Buckle up, because I'm about to roll out Borepatch's Second Law of Security.Let's think about a brick-and-mortar bank. It will be in a building with decent security. More importantly, the security will be well understood. There are people whose business it is to know how long it will take someone to knock a hole in drywall, or cinder block, or vault steel. Or bullet-proof glass, for that matter. When you design a bank branch office, you take these things into account.
You also take area characteristics into account. Is it a good neighborhood? High traffic? Well lighted? All of these effect the security of your customers when they're not in your building. The system of the branch office is more than just the building.
So what's the system of the online mobile bank? We need to understand this to understand the risks of the different system components to get a good understanding of the overall risk.
There's the web site itself (logo blurred out here to protect the guilty). My experience is that you'll find the best security in the Defense Department. Very close behind that is security at the major banks. I have made some snide comments in the past about online banking, but the problem isn't that they don't have cutting-edge technology, or skilled operations personnel, or processes and procedures that are backed by executive management. Someone's in charge of the system - you can ask the question who's the online security guy and get an answer. While there will always be the occasional security vulnerability in the web portal, the risk here is low.
There's the Internet, that sits between you and the web site. Security is lousy here, but the encryption used to scramble your data while it flies over Al Gore's Intarwebz is so good that the risk here is basically non-existent.
There's your phone, and your phone's browser. Technology is moving very, very fast here, which means that security is an after thought. You have many different vendors - one makes the phone, a different one makes the software, and a third one that sets everything up. For me, it's some company in China who makes the phone, and Apple who makes the software (OS X and Safari), and AT&T who sets things up.
So when it comes to your phone, you are the "online security guy". You need to configure the phone securely and make sure that things are working correctly. Not your bank - after all, it's your phone, not theirs.
So what's the risk of the overall banking system? Negligible risk in the banking web site and Internet transport, but indeterminate risk in your phone.
In an engineering sense, "indeterminate" is a Bad Thing, because you can't estimate costs and risks. It's more than just Ted has a bad feeling going on here, there are serious issues that you need to know before you know if the overall online mobile banking system has unacceptable risk:
Do you have a password on your phone? Passwords aren't the be all and end all, but not having a password means that any Tom, Dick, or Harry can use your phone.You have some sort of chance of knowing the answers to the first two questions; you have almost no chance at all of getting an answer to the third. Even more importantly, your bank can't find out, either - the web site can ask the browser a number of interesting questions, but not about these things.
Is all the data stored on your phone encrypted? If your company gives you a phone, and there's a guy in IT who sets things up, the answer very well may be "yes". Otherwise, it's almost certainly "no". "No" means that any Tom, Dick, or Harry can get your data if they get your phone.
Does your phone's browser clear all sensitive data when you're done browsing? Does it remember passwords? Does it save cookies? Does it have some sort of optimization to make it run faster, that involves saving a bunch of data so that the next time you go to http://uberl33tbank.com you get peppy load times?
So we're back to indeterminate. This is Bad Security juju, and this is where I will point to Borepatch's Second Law of Security:
Assume that all data on your phone is public data if you ever lose your phone.Remember Tina Sherman? She has a loving husband - so loving, in fact, that he used his camera phone to take some photos of her in the all-together. Then he lost the phone. Then Mrs. Sherman found that she was the (ahem) star of a raft of web sites.
Imagine now that instead of naughty pix of the little lady, Mr. Sherman had his banking account and password on his phone.
Indeterminate.
So if you know how the system works and think that the benefits outweight the costs, then go ahead. That, in fact, is the way that the system is supposed to work. As for me, I don't think I'm smart enough to figure out what my phone is doing.
So my recommendation to you is use an ATM, or if you absolutely must bank online, use your home computer. Just follow the 2 Simple Rules for Safer Browsing.
Your mileage may vary, void where prohibited, do not remove under penalty of law.
UPDATE 19 January 2009 21:14: Chris Byrne left a information-rich comment that is well worth your while.
The Two Things about George W. Bush
The Two Things is an interesting analytical framework, because it forces you to prioritize. I quite like their Two Things about economics: One: Incentives matter. Two: There’s no such thing as a free lunch. That's a workable understanding that you can use to see why the bailouts are a slow motion train wreck, headed our way.
So what are the Two Things about George W. Bush? At the close of his administration, we have the advantage of retrospect.
Personally, I agree with Obama:
stupid Republican party, though - that #2 pretty much did you guys in.
So what are the Two Things about George W. Bush? At the close of his administration, we have the advantage of retrospect.
One: He got the war on terror right, because he was stubborn. Most Washingtonites would have given up; he didn't. This was a big, big win.There's no question that history will be kinder to GWB than the press was. His big government mindset will be continued under Obama, and Iraq is doing well enough that it's the O-Man's to lose. The media is already walking back from the cliff, so Bush's war on terror legacy is safe.
Two: He was one of the worst of the Big Government insiders. Like LBJ, he chose guns and butter, bigger bureaucracy (No Child Left Behind), and the nanny state (McCain Feingold). This was a big, big miss.
Personally, I agree with Obama:
I think personally he is a good man who loves his family and loves his country. And I think he made the best decisions that he could at times under some very difficult circumstances.Good luck to the
Do It For The Children
I posted last week about unanticipated consequences. Offered for your consideration, CoyoteBlog on Phoenix building codes designed to keep small children from falling into swimming pools and drowning. Who could possibly object to that fer crying out loud?
Of course, everyone who voted for the codes thought of everything, right?
Dunno, maybe he has guns, too.
And for all the good Doobees who let their kids burn up in a fire, I'm sure that there will be the proper amount of brow furrowing and tut-tutting and mistakes-were-made noises by all the bien pensants.
Of course, everyone who voted for the codes thought of everything, right?
Can anyone see any possible problem with making it impossible for small children to exit the house? Perhaps, say, in a fire? Once I bring my house up to code, because none of the children’s wing of the house has any window or door except to the pool area, the state will have made it absolutely impossible for small children to escape in a fire. Yes, the state has forced me to turn the back of my house into a fire trap for kids. That is, of course, unless I reverse all the changes 5 seconds after the inspector leaves my property, which of course I would never, ever do because I am a good American who pledged allegiance to the state every shool day of my childhood.And thus is created another Hardened Criminal, intentionally violating our laws. If he gets out of line on something (oh, I don't know, how about Global Warming orthodoxy), he should be vigorously investigated.
Dunno, maybe he has guns, too.
And for all the good Doobees who let their kids burn up in a fire, I'm sure that there will be the proper amount of brow furrowing and tut-tutting and mistakes-were-made noises by all the bien pensants.
Marketing Win, and Fail
Happy Birthday
Dolly Parton is one of my favorite entertainers. Love her or hate her, what you see is what you get. This interview by the BBC's Parkenson is typical. I looked for (but couldn't find) her appearance on Graham Norton, which is worth Tivoing. Happy birthday, Dolly!
And Happy Birthday to two of the giants of the Industrial Revolution, James Watt (creator of the first practical steam engine) and Sir Henry Bessemer, who created a process to make Steel dirt cheap. Our would wouldn't remotely be what it is today without them, but they weren't as funny as Dolly.
And Happy Birthday to two of the giants of the Industrial Revolution, James Watt (creator of the first practical steam engine) and Sir Henry Bessemer, who created a process to make Steel dirt cheap. Our would wouldn't remotely be what it is today without them, but they weren't as funny as Dolly.
Sunday, January 18, 2009
Tuxedos, Breakout, and 4k of RAM
Atari famously introduced Pong in the 1970s, on what we'd now call a game console (the Atari 2600). Well gosh, said the marketing folks, how about a whole home computer? This way parents would drop big bucks so that little Junior would get all computer-edumacated. Pong would be the sugar coating to launch a thousand hackers, if you'll let me mix my metaphors.
Behold the Atari 400 home computer. It had a CPU, 4k of RAM, a slot for software cartridges, and a steep price tag. The keyboard was a touch-sensitive film, rather than full-motion keys. Kind of weird, since you would typically see these in industrial environments, and the Atari was definitely not designed for that. Maybe they were worried about coffee spills.
I don't remember the home of 1978 being this much fun. With the price tag, maybe only people who owned Tuxedos could afford it:
The Atari 400 was pretty quickly replaced by the Atari 800, which expanded to a whopping 48k of RAM. It still had the goofy cartridge slot (getcher Tux on and let's play Breakout!), but at least it had a real keyboard.

Alas, all things must end, and Atari was no exception. High flying in the late 1970s and early 1980s (Space Invaders made the 2600 one of the best selling Christmas presents of 1979), the company was poorly managed and went under. I actually had a job interview with a company (Ford Aerospace, which also went under; I didn't get caught because I didn't take the job) that had taken over Atari's tricked out Earthquake-proof headquarters. One of the guys who interviewed me described being in the building during the 1991 quake, and seeing the shockwave approach from his office window. The shock passed by with no effect, as the huge shock absorbers in the basement did what they were designed to to.
Behold the Atari 400 home computer. It had a CPU, 4k of RAM, a slot for software cartridges, and a steep price tag. The keyboard was a touch-sensitive film, rather than full-motion keys. Kind of weird, since you would typically see these in industrial environments, and the Atari was definitely not designed for that. Maybe they were worried about coffee spills.
I don't remember the home of 1978 being this much fun. With the price tag, maybe only people who owned Tuxedos could afford it:The Atari 400 was pretty quickly replaced by the Atari 800, which expanded to a whopping 48k of RAM. It still had the goofy cartridge slot (getcher Tux on and let's play Breakout!), but at least it had a real keyboard.

Alas, all things must end, and Atari was no exception. High flying in the late 1970s and early 1980s (Space Invaders made the 2600 one of the best selling Christmas presents of 1979), the company was poorly managed and went under. I actually had a job interview with a company (Ford Aerospace, which also went under; I didn't get caught because I didn't take the job) that had taken over Atari's tricked out Earthquake-proof headquarters. One of the guys who interviewed me described being in the building during the 1991 quake, and seeing the shockwave approach from his office window. The shock passed by with no effect, as the huge shock absorbers in the basement did what they were designed to to.
Good Book, Bad Book
The Barnes and Noble guy patiently explained to us that they were both "coffee table" books. You've never been to dinner at Mom's, Scooter. Hugh Heffner could not be reached for comment. Which brings to mind this quality bit of snark:
"If I were in charge of the TSA's budget, I'd give most of it back."
Bruce Schneier is a computer security guru who also spends a lot of time dealing with non-computer security. Reason has a must-read interview with him where he talks about the Transportation Security Administration (TSA) and how it is spending a lot of time and effort on things that won't make security better.
The TSA focuses too much on specific tactics and targets. This makes sense politically, but is a bad use of security resources. Think about the last eight years. We take away guns and knives, and the terrorists use box cutters. We confiscate box cutters and knitting needles, and they put explosives in their shoes. We screen shoes, and they use liquids. We take away liquids, and they'll do something else. This is a dumb game; the TSA should stop playing. Some screening is necessary to stop the crazy and the stupid, but it's not going to stop a professional terrorist attack. We don't need more and better screening; we need less. On the other hand, I like seeing the direction they're heading in terms of behavioral profiling, though we need to be careful. Done wrong, it's nothing more than stereotyping; but done right, it can be very effective. It needs more focus on people and less on objects. We can't manage to keep weapons out of prisons; we'll never keep them out of airports. Oh, and stop the ID checking—the notion that there is this master list of terrorists that we can check people off against is just plain silly.It's simply filled to the brim with basic, sensible ideas that you know will never see implementation, because they're too sensible:
Spending money on airport/airplane security only makes sense if the bad guys target airplanes. In general, money spent defending particular targets or tactics only makes sense if we can guess them correctly. If tactics and targets are scarce, defending against specific ones makes us safer. If tactics and targets are plentiful—as they are—it only forces the bad guys to pick new ones.More:
I believe that approximately two security improvements since 9/11 have made airplane travel safer: reinforcing the cockpit door, teaching passengers they have to fight back, and—maybe—sky marshals.The article also discusses the idiotic security measures that will be at the inauguration, that will pose a public safety hazard.
Sigh.
Saturday, January 17, 2009
ZOMG! Nazi Zombies!
#2 Son was showing me Call of Duty: World At War, and what did I see? Nacht der Untoten. Hmmm, says I: could this be what it sounds like?
You bet!

Shotguns, Garands, machine guns, and frickin' flame throwers! AND you can play multiplayer on X-Box live.
I'm guessing that posting will be (ahem) light this weekend ...
You bet!
Shotguns, Garands, machine guns, and frickin' flame throwers! AND you can play multiplayer on X-Box live.
I'm guessing that posting will be (ahem) light this weekend ...
Subscribe to:
Posts (Atom)
